[HN Gopher] TLS Certificate Transparency logs don't always talk ...
       ___________________________________________________________________
        
       TLS Certificate Transparency logs don't always talk to you
        
       Author : rdpintqogeogsaa
       Score  : 8 points
       Date   : 2022-06-08 18:40 UTC (4 hours ago)
        
 (HTM) web link (utcc.utoronto.ca)
 (TXT) w3m dump (utcc.utoronto.ca)
        
       | throwaway787544 wrote:
       | Logs are there because any person at any CA can generate a cert
       | for your domain and we want to know when that happens. We should
       | fix that.
       | 
       | A new standard could dictate that registrars and CAs have to work
       | together. Specifically, customer uploads a public key to a
       | registrar, and a CA has to use registrar's public key to validate
       | a CSR. This makes it impossible to create a valid certificate
       | without the domain owner's key - and not whoever took over the
       | domain record for the moment that the CA validated. The browser
       | should validate that the cert was signed using the key from the
       | registrar.
       | 
       | In this way even a rogue CA cert can't work on a client. Only a
       | cert created by the domain owner will be valid. So only one CA
       | and one key can create a valid cert.
        
       | rektide wrote:
       | With specs like WebBundle, sites could self-sign the log content,
       | in a way where other people could securely mirror/cache another
       | sites log resources in a way that's still clear & secure.
        
       ___________________________________________________________________
       (page generated 2022-06-08 23:02 UTC)